Last month I watched a CPA paste a client’s full P&L — with the client’s name, EIN, and revenue figures — directly into ChatGPT Plus.
“It’s the paid version,” he said. “It’s private.”
It’s not.
This is the single biggest professional risk accountants face with AI right now, and most don’t know they’re taking it. Not because they’re careless — because the privacy policies are deliberately confusing, and the AI companies aren’t exactly racing to make them clearer.
Here’s what’s actually happening with your data when you use AI for client work.
OpenAI’s privacy policy for consumer products (ChatGPT Free and ChatGPT Plus) states that conversations may be used to improve their models. This means:
ChatGPT 5.3, released this month, has expanded the model’s search capabilities significantly. The system now performs 10+ fan-out searches per query and evaluates source authority more aggressively. What hasn’t changed: the training data policy for consumer plans.
You can toggle off “Improve the model for everyone” in ChatGPT settings. But this opt-out only prevents future training — it doesn’t retroactively remove anything you’ve already submitted. And the setting resets when you create a new account or sometimes after updates.
The bottom line: ChatGPT Plus ($20/month) is not a professional-grade privacy solution for accountant client data. Period.
Anthropic’s position is slightly better but still has traps.
Claude Free conversations can be used for training. Claude Pro ($20/month) has a training opt-in — meaning Anthropic doesn’t train on your data by default on the paid plan. But the opt-in can be toggled ON without you noticing, especially during onboarding flows where checkboxes are pre-selected.
With the release of Claude Opus 4.7 this month — Anthropic’s most capable model — more accountants are upgrading to Pro to access it. That’s fine. Just make sure your training toggle is set to OFF and check it periodically.
The bottom line: Claude Pro is safer than ChatGPT Plus if configured correctly. But “if configured correctly” is doing a lot of work in that sentence.
Most professionals using AI are handling their own data. A marketer pasting their own ad copy into ChatGPT isn’t creating a confidentiality issue. A product manager brainstorming feature ideas isn’t breaching anyone’s trust.
Accountants are different. We handle other people’s most sensitive financial information. Client names paired with revenue figures. SSNs on tax documents. EINs on business filings. Compensation details. Accounts receivable that reveal who owes what to whom.
When this data enters a consumer AI system that trains on inputs, it doesn’t just become part of a model. It becomes part of a model that other people use. The risk isn’t that someone will pull up your client’s exact P&L from ChatGPT — that’s not how training works. The risk is subtler:
That last point is the one that should keep you up at night. Not because regulators are actively hunting for it — they’re not, yet. Because when they do, “I didn’t know” won’t be a defense.
Both OpenAI and Anthropic offer business-tier plans with contractual privacy guarantees:
ChatGPT Team ($25-30/user/month): OpenAI contractually commits to not training on your data. Conversations are not used for model improvement. Admin controls for team management. SOC 2 compliant.
ChatGPT Enterprise: Everything in Team plus advanced security, longer context windows, and dedicated support. Pricing varies.
Claude Team ($25-30/user/month): Anthropic contractually does not train on Team plan data. No human review of conversations. Admin controls. Better for firms that want Claude’s stronger performance on accounting tasks.
Claude Enterprise: Single-tenant deployment options, advanced security, priority access to new models like Opus 4.7.
The price difference between consumer ($20/month) and team ($25-30/month) is $5-10 per month. For the contractual privacy guarantee alone, this is the most obvious professional expense I can think of.
If you can’t or won’t upgrade to a business plan, anonymization is your minimum standard.
Before pasting ANY client data into a consumer AI tool, run through these five steps:
Step 1: Copy. Copy the data into a temporary document. Never work from the original file.
Step 2: Delete. Remove all NEVER-tier data:
Step 3: Replace. Swap identifying information with generic placeholders:
Step 4: Mask. Anonymize remaining identifying details:
Step 5: Review. Read the anonymized version one final time. Ask yourself: could someone identify this client from the remaining data? If the answer is even “maybe,” go back to Step 3.
Dollar amounts, percentages, transaction descriptions, and dates are generally safe to keep — they’re useful for analysis and meaningless without identifying context.
This protocol takes 30-60 seconds per prompt. It’s not fun. It’s necessary.
Whether you’re a solo practitioner or run a 20-person firm, here are four actions you should take immediately:
1. Audit your current AI usage. Find out what tools your team is actually using. Not what they’re supposed to use — what they’re actually pasting client data into. The gap between policy and practice is usually large.
2. Upgrade to business plans. ChatGPT Team or Claude Team. Pick one (or both). Make it a firm expense. The $25-30/user/month is cheaper than one E&O claim.
3. Create a one-page AI policy. It doesn’t need to be a legal document. It needs to answer three questions: What AI tools are approved? What data can be pasted into AI? What verification steps are required before using AI output?
4. Add an AI clause to your engagement letters. Something simple: “Our firm may use AI-assisted tools for certain analytical and administrative tasks. All AI-generated output is reviewed by a licensed professional before use. Client data is anonymized before processing through any external AI system, and we use enterprise-grade AI platforms with contractual privacy protections.”
This isn’t legal advice. Talk to your attorney about the specific language. But having something is dramatically better than having nothing.
Here’s the part that’s easy to miss while worrying about privacy: the firms that handle AI data governance well will have a competitive advantage.
Enterprise clients are starting to ask about AI in their RFPs. “Does your firm use AI? How do you protect our data?” The firms that can answer these questions clearly — with specific policies, enterprise-grade tools, and documented protocols — will win engagements that firms without answers will lose.
Data privacy isn’t just a risk to manage. Done right, it’s a selling point.
The privacy landscape for AI is going to get more complex, not simpler. The Trump administration is pushing for unified national AI regulation to prevent a patchwork of state-level rules. Whatever emerges will almost certainly include data handling requirements for professional services.
Meanwhile, both OpenAI and Anthropic are aggressively expanding enterprise features. OpenAI’s internal strategy documents describe a push to grow business revenue from 40% to 50% of total revenue by year-end, specifically by building features that increase “switching costs” for enterprise clients.
For accountants, this means: the tools are going to get better and more secure. But the current moment — right now, April 2026 — is the gap between capability and governance. The AI is powerful enough to be useful and accessible enough to be misused.
Close the gap in your practice before someone closes it for you.
The free PDF includes a Data Safety Quick Guide with the complete tri-tier system (NEVER / ANONYMIZE / SAFE) and the 5-step anonymization workflow. Download it here.
Get 50 copy-paste prompts delivered to your inbox — free.
Get the Free PDF →